Data Processing Agreement
Effective date: 1 August 2026
Mangroove FZ-LLCLicense no. 47035430
FDBC5835
Compass Building
Al Shohada Road
Al Hamra Industrial Zone-FZ
Ras Al Khaimah
United Arab Emirates
info@creatorspa.io
This Data Processing Agreement (“DPA”) forms part of the CreatorsPA Terms of Use and applies where Mangroove FZ-LLC processes Personal Data on behalf of a Customer in connection with CreatorsPA.
This DPA is entered into between Mangroove FZ-LLC (“CreatorsPA”, “we”, “us”, “our” or the “Processor”) and the person or entity that has accepted the CreatorsPA Terms of Use and uses the Service as a controller or processor of Personal Data (“Customer”, “you” or “your”).
This DPA is incorporated automatically into the Terms of Use and does not require a separate signature. If CreatorsPA does not process Personal Data on your behalf, this DPA does not apply to that processing.
1. Purpose and Scope
This DPA governs the processing of Personal Data by CreatorsPA on behalf of the Customer when providing the CreatorsPA service. It is intended to satisfy applicable requirements for controller-processor arrangements under applicable Data Protection Laws, including the GDPR and UK GDPR where relevant.
CreatorsPA may also process certain information for its own purposes as an independent controller. That processing is outside the scope of this DPA and is governed by the CreatorsPA Privacy Policy. Examples include account administration, login information, security records, subscription management, billing references, legal compliance and similar operational information.
2. Definitions
For purposes of this DPA:
- “Applicable Data Protection Law” means privacy and data protection laws applicable to the processing covered by this DPA, including, where applicable, the GDPR and UK GDPR.
- “Controller” means the person or entity that determines the purposes and means of processing Personal Data.
- “Customer Data” means Personal Data processed by CreatorsPA on behalf of the Customer in connection with the Service.
- “Data Subject” means an identified or identifiable natural person whose Personal Data is processed.
- “GDPR” means Regulation (EU) 2016/679.
- “Personal Data” has the meaning given under Applicable Data Protection Law.
- “Processing” or “Process” has the meaning given under Applicable Data Protection Law.
- “Processor” means a person or entity that processes Personal Data on behalf of a Controller.
- “Security Incident” means an accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data processed under this DPA.
- “Service” means CreatorsPA and its related features, integrations and functionality.
- “Subprocessor” means a third party engaged by CreatorsPA to process Customer Data in connection with providing the Service.
- “SCCs” means the then-applicable Standard Contractual Clauses approved by the European Commission for international transfers of Personal Data.
- “UK Addendum” means the applicable UK International Data Transfer Addendum to the European Commission SCCs approved by the UK Information Commissioner.
3. Roles of the Parties
For Personal Data processed under this DPA:
- the Customer acts as Controller and CreatorsPA acts as Processor; or
- where the Customer itself acts as a Processor on behalf of another Controller, CreatorsPA acts as a Subprocessor.
The Customer determines the purposes for which Customer Data is processed. CreatorsPA processes Customer Data only to provide, maintain, secure and support the Service in accordance with (1) the Terms of Use, (2) this DPA, (3) the Customer’s actions and instructions within CreatorsPA, and (4) other written instructions expressly accepted by CreatorsPA.
CreatorsPA acts as an independent Controller for information it processes for its own legitimate operational purposes, such as account administration, authentication, subscription management, security, fraud prevention, legal compliance and support administration.
4. Customer Instructions
The Customer instructs CreatorsPA to process Customer Data as reasonably necessary to provide the Service and perform the functionality selected by the Customer. Actions taken by the Customer through the Service, including connecting a channel, requesting AI generation, approving content, creating a calendar event or requesting another feature, constitute documented instructions for purposes of this DPA.
Any additional or special instruction outside the normal functionality of CreatorsPA will only become binding if CreatorsPA accepts it in writing. CreatorsPA will not process Customer Data for purposes unrelated to providing, operating, securing or supporting the Service unless required by applicable law, or the Customer has provided a separate lawful instruction.
If CreatorsPA reasonably believes that a Customer instruction violates Applicable Data Protection Law, we may suspend that instruction and inform the Customer unless we are legally prohibited from doing so.
5. Customer Responsibilities
The Customer is responsible for complying with its obligations under Applicable Data Protection Law. In particular, the Customer is responsible for:
- having a lawful basis for processing Customer Data;
- providing any legally required privacy notices;
- obtaining any required consent or permission;
- ensuring that Personal Data submitted to CreatorsPA has been collected lawfully;
- ensuring that its instructions to CreatorsPA are lawful;
- respecting the rights of Data Subjects;
- having authority to process data obtained through connected social channels;
- obtaining any necessary permissions for people appearing in images, video or audio;
- protecting its account credentials; and
- determining whether its intended use of CreatorsPA is appropriate for the Personal Data involved.
Where Customer Data concerns a minor, the Customer is responsible for ensuring that the processing is lawful and that any required parental or guardian consent has been obtained. CreatorsPA does not independently collect age or date-of-birth information about minors appearing in Customer Content.
6. Special Categories of Personal Data
CreatorsPA is not designed for the intentional processing of special categories of Personal Data, including information concerning health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data or biometric data used for unique identification.
Customers should not intentionally submit such information unless the processing is lawful, necessary for the Customer’s use of the Service and permitted by CreatorsPA. Images, video, faces and voice recordings may be processed by CreatorsPA as ordinary content. CreatorsPA does not use facial images, voice recordings or similar information for biometric identification or authentication.
7. Nature and Purpose of Processing
CreatorsPA may process Customer Data to provide functionality requested by the Customer, including:
- storing and managing content;
- maintaining conversation history;
- generating text, images, voice or video;
- assisting with content planning and creation;
- performing trend research;
- connecting authorised social media accounts;
- retrieving social media information;
- retrieving comments;
- preparing and publishing approved content;
- preparing approved comment replies;
- maintaining publishing history;
- creating Google Calendar events at the Customer’s direct request;
- providing support and troubleshooting;
- detecting technical problems;
- protecting the security and integrity of the Service;
- detecting abuse or violations of the Terms of Use;
- maintaining backups and disaster recovery systems; and
- complying with lawful instructions and legal obligations.
Customer Content is sent to an AI provider only when the Customer actively chooses to use a function requiring that AI processing. CreatorsPA does not routinely send Customer Content to AI providers in the background for unrelated purposes.
8. Categories of Personal Data
Depending on the features used by the Customer, Customer Data may include:
8.1 Content and conversation data
- text entered by the Customer; prompts; saved conversations; AI responses;
- captions; drafts; scripts;
- images; photographs; voice recordings; video;
- content descriptions; generated content; and
- other material supplied through the Service.
Conversations between the Customer and the CreatorsPA team are stored so that the Service can retain context and build on previous work. When a Customer sends a new message, only the recent conversation context reasonably required to process the request is sent to the relevant AI provider rather than the Customer’s complete conversation history. Image prompts and trend-analysis requests may be processed for the requested function without necessarily being retained as conversation history.
8.2 Connected social channel data
Depending on the platform and features used, CreatorsPA may process channel and profile information, channel identifiers, profile names, comments, publishing history, post information, YouTube video titles and descriptions, links to media hosted by third-party platforms, and OAuth access and refresh tokens.
CreatorsPA does not normally copy or permanently store social platform media files solely because a social account is connected. Media may remain hosted by the relevant platform, while CreatorsPA stores references or links where required for the Service.
8.3 Analytics information
For posts published through CreatorsPA, performance information such as views, likes, comment counts and, on Facebook, shares may be retrieved from the connected platform and cached with the relevant post.
These metrics are refreshed at most every 30 minutes. CreatorsPA does not maintain a historical time series of those metrics.
CreatorsPA does not currently retrieve reach, watch time, subscriber or follower counts, or audience demographics through this functionality.
8.4 Generated media
Everything generated for the Customer — images, video and voice — is downloaded into CreatorsPA’s EU-based storage as soon as it is produced. CreatorsPA does not store links pointing at an AI provider’s servers, so Customer Content does not depend on a provider link remaining available. Files are held in private storage and served through short-lived signed links. The assistant’s read-aloud audio is streamed to the browser and never stored.
8.5 Support information
Where the Customer contacts support, Customer Data may include information voluntarily supplied for troubleshooting, such as screenshots, error messages, content examples, channel identifiers or other information needed to investigate the issue.
9. Categories of Data Subjects
Customer Data may relate to the Customer; people appearing in Customer Content; individuals whose voices or likenesses appear in content; people commenting on or interacting with connected channels; collaborators; customers or clients of the Customer; people the Customer chooses to reference in content; and minors appearing in lawfully submitted Customer Content.
CreatorsPA does not independently establish a relationship with those third-party Data Subjects merely because their Personal Data is included in Customer Data.
10. Data We Process as Controller
Certain information is processed by Mangroove FZ-LLC for its own purposes and is not Customer Data processed under this DPA. This may include:
- account name and email address;
- Google authentication information;
- Google account identifier (we do not receive or store the Google profile picture);
- last sign-in date;
- subscription status;
- Paddle customer and subscription references;
- plan information; renewal date;
- security and administrative logs;
- support correspondence;
- legal and compliance records; and
- information required to operate and secure the Service.
This processing is governed by the CreatorsPA Privacy Policy. Signing in with Google requests identity only — name and email address. Permission to reply to YouTube comments is requested separately when a channel is connected, and permission to create calendar events is requested separately at the first reminder request. Gmail and Google Drive are never requested. Adding a further YouTube channel later requests YouTube permission only.
11. Payments
CreatorsPA does not receive or store payment card numbers, bank account details or payment credentials. Payments are handled by Paddle as merchant of record under Paddle’s applicable terms.
CreatorsPA may store limited non-sensitive identifiers received from Paddle, such as customer identifier, subscription identifier, plan, subscription status and renewal date. These are used to provide the correct subscription access and administer the Customer’s account and are processed by CreatorsPA as Controller rather than under the Processor activities governed by this DPA.
12. Google Calendar
CreatorsPA currently supports Google Calendar where the functionality is available. CreatorsPA does not read or import the Customer’s existing calendar. Calendar information is processed only when the Customer directly instructs CreatorsPA to create an event. The information required for that event is sent to Google and is not retained by CreatorsPA as a stored copy after the event has been created.
13. AI Processing
CreatorsPA uses third-party AI providers to perform specific functions requested by the Customer. Depending on the feature, these may include providers for text generation, image generation, video generation, voice generation and trend analysis.
Customer Data is sent to an AI provider only where required for the specific function activated by the Customer. AI providers engaged as subprocessors are required to process Customer Data under contractual safeguards and not for their own independent purposes. CreatorsPA does not permit Customer Content processed through these integrations to be used to train the providers’ general AI models.
Some AI providers may retain inputs temporarily, typically for up to 30 days, for legitimate security, abuse monitoring or service-protection purposes before deletion, subject to their contractual terms.
14. No Training on Customer Content
CreatorsPA does not use Customer Content to train or improve CreatorsPA’s own general AI models. CreatorsPA does not authorise its AI subprocessors to use Customer Content for training their general models.
This does not prevent CreatorsPA from using anonymised and aggregated operational information that does not contain identifiable Customer Content to improve the security, reliability or operation of the Service.
15. Subprocessors
The Customer grants CreatorsPA general written authorisation to engage subprocessors where reasonably necessary to provide the Service.
The current list of subprocessors is maintained separately on the CreatorsPA Subprocessors page.
The list may include providers supporting database and file storage, application hosting, transactional email, authentication, AI processing, public social media data retrieval, support email infrastructure, and other infrastructure necessary to provide the Service.
One of those providers is SocialCrawl, used for public social media data retrieval. When the Customer researches a channel or topic, CreatorsPA sends a query — such as a channel name or keyword — together with the chosen platform and time range, and receives publicly available platform data in return. No account data or Customer Content is sent. Trend results are aggregated without the author’s identity; creator search and networking results keep public profile details so that a relevant comment can be drafted, and networking records are deleted automatically after 14 days. Processing may occur outside the EU/EEA under applicable transfer safeguards.
CreatorsPA requires each subprocessor that processes Customer Data to be subject to contractual obligations providing an appropriate level of data protection for the processing performed. CreatorsPA remains responsible for its subprocessors to the extent required by Applicable Data Protection Law.
16. Changes to Subprocessors
CreatorsPA may add, replace or remove subprocessors. Where required by Applicable Data Protection Law, CreatorsPA will provide at least 30 days’ advance notice of a new or replacement subprocessor. Notice may be sent to the email address associated with the Customer’s CreatorsPA account and may direct the Customer to the updated Subprocessors page.
The Customer may object during that period where it has reasonable and documented grounds relating specifically to data protection. The parties will attempt in good faith to resolve a valid objection. Where no reasonable solution is available, CreatorsPA may modify the affected processing, offer a commercially reasonable alternative where available, discontinue the affected feature, or permit termination of the affected Service where required by Applicable Data Protection Law.
An objection based solely on commercial preference or a general dislike of a supplier does not constitute a valid data-protection objection.
17. Confidentiality
CreatorsPA ensures that persons authorised to process Customer Data are subject to appropriate confidentiality obligations. Access to production data is restricted to authorised personnel and is permitted only where reasonably necessary, including for troubleshooting, investigating a technical fault, investigating a Security Incident, investigating misuse or a complaint, complying with a lawful request, or maintaining the integrity of the Service. Access is granted on a need-to-know basis.
18. Security Measures
CreatorsPA maintains technical and organisational measures designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Current measures include:
- TLS encryption for data in transit;
- AES-256 encryption at rest through CreatorsPA’s storage infrastructure, including encrypted backups;
- database row-level security;
- logical separation of user data;
- access controls restricting production access to authorised personnel;
- need-to-know production access;
- confidentiality obligations for authorised personnel;
- audit logging of sensitive administrative actions;
- secure storage of application secrets in the hosting environment rather than source code;
- restricted production system access;
- backup and recovery procedures;
- abuse and security monitoring; and
- minimisation of unnecessary tracking technologies.
CreatorsPA does not use third-party advertising or analytics tracking cookies for the operation described in this DPA. Security measures may evolve as the Service changes, provided that CreatorsPA does not materially reduce the overall level of protection required by Applicable Data Protection Law. CreatorsPA does not currently claim SOC 2, ISO 27001 or similar certification.
19. Security Incidents
CreatorsPA maintains procedures for responding to suspected or confirmed Security Incidents. Where a Security Incident involving Customer Data is confirmed, CreatorsPA will take reasonable steps to investigate the incident, contain and mitigate its effects, preserve relevant evidence, document the incident, take reasonable measures to prevent recurrence, and notify the affected Customer without undue delay where required by Applicable Data Protection Law.
The notification will include information reasonably available to CreatorsPA that may assist the Customer in meeting its own legal notification obligations. Information may be provided in stages where it is not reasonably possible to provide all relevant information at the same time. Notification of a Security Incident does not constitute an admission of fault or liability by CreatorsPA.
20. Data Subject Requests
If CreatorsPA receives a request directly from a Data Subject concerning Customer Data processed under this DPA, CreatorsPA will not independently respond to the substance of the request unless instructed by the Customer or required to do so by applicable law. Where reasonably possible, CreatorsPA will direct the Data Subject to the Customer.
Taking into account the nature of the processing, CreatorsPA will provide reasonable assistance to the Customer with requests concerning access, correction, deletion, restriction, portability, objection and other applicable Data Subject rights. Such additional assistance may be provided at the Customer’s expense where it requires work outside the normal functionality of the Service.
21. Regulatory Assistance and DPIAs
Taking into account the nature of the processing and information reasonably available to CreatorsPA, we will provide reasonable assistance with Data Protection Impact Assessments, consultations with supervisory authorities, regulatory inquiries relating to Customer Data, and demonstrating compliance with applicable controller obligations. Additional assistance outside the normal operation of the Service may be charged to the Customer at CreatorsPA’s reasonable cost.
22. Audits and Compliance Information
CreatorsPA will make information reasonably necessary to demonstrate compliance with this DPA available to the Customer. No more than once in any 12-month period, unless required by Applicable Data Protection Law or following a material Security Incident, the Customer may request reasonable security or compliance information relevant to the processing.
CreatorsPA may satisfy such a request by providing available security documentation, policies, questionnaires, audit summaries, third-party reports or equivalent compliance information.
An on-site or intrusive audit may only be requested where required by Applicable Data Protection Law or applicable SCCs, and the information reasonably available from CreatorsPA is insufficient. Any audit must be conducted on reasonable advance written notice, occur during normal business operations, avoid unreasonable disruption, protect other customers’ confidential information, not require disclosure of source code, credentials or information that could compromise security, and be at the Customer’s expense unless required otherwise by mandatory law.
23. Data Location
CreatorsPA’s primary database and file storage for account data and Customer Content is hosted in the European Union. CreatorsPA currently uses EU-based database and storage infrastructure in Frankfurt, Germany.
Transactional email is delivered through Resend. Email delivery may use Resend’s Ireland region, while certain Resend account data, email metadata, logs and API records may be stored in the United States.
Support email received through info@creatorspa.io is handled through Google Workspace.
The application is hosted through Vercel, which may process technical information required to deliver and secure the Service.
Certain processing may also involve access to or processing of Customer Data outside the EU/EEA, including AI processing by approved providers, authorised access to production systems from the United Arab Emirates, and other processing disclosed on the Subprocessors page.
CreatorsPA uses appropriate transfer safeguards where required by Applicable Data Protection Law.
24. International Data Transfers
Where Customer Data subject to the GDPR is transferred to a country that does not benefit from an applicable adequacy decision or other valid transfer mechanism, CreatorsPA will use an appropriate safeguard as required by Applicable Data Protection Law. Where necessary, the European Commission Standard Contractual Clauses adopted under Decision (EU) 2021/914 are incorporated into this DPA by reference.
24.1 EU SCC module
Where the Customer is a Controller and CreatorsPA is the Processor, Module Two — Controller to Processor applies. Where the Customer is itself a Processor and CreatorsPA acts as a Subprocessor, Module Three — Processor to Processor applies to the extent necessary.
For purposes of the SCCs: the Customer is the data exporter; Mangroove FZ-LLC is the data importer; the information contained in this DPA and its schedules completes the relevant Annexes to the SCCs where applicable; the supervisory authority will be determined in accordance with the SCCs and Applicable Data Protection Law; the governing law for the SCCs will be the law of Ireland, where a choice is required and legally permitted; and the courts of Ireland will have jurisdiction for disputes arising specifically under the SCCs where required by the SCCs.
The SCCs prevail over this DPA to the extent of a direct conflict concerning an international transfer governed by those SCCs.
25. UK International Transfers
Where Customer Data subject to UK GDPR is transferred in a manner requiring an appropriate safeguard, the then-current UK International Data Transfer Addendum to the European Commission SCCs will apply to the extent required by UK Data Protection Law.
For those transfers: the applicable EU SCCs are incorporated as described above; the UK Addendum is incorporated by reference; the information in this DPA and its schedules may be used to complete the applicable tables of the UK Addendum; and mandatory UK law and jurisdiction provisions contained in the UK Addendum will apply to the relevant transfer. The UK Addendum prevails over inconsistent terms of this DPA only to the extent required for the applicable UK restricted transfer.
26. Onward Transfers
Where CreatorsPA permits a subprocessor outside the EU/EEA or UK to process Customer Data, CreatorsPA will require an appropriate contractual and legal transfer mechanism where required. This may include the SCCs, the UK Addendum, an applicable adequacy mechanism, or another lawful transfer safeguard permitted by Applicable Data Protection Law. CreatorsPA will assess and implement additional safeguards where required by applicable transfer law.
27. Connected Social Accounts
CreatorsPA may store access and refresh tokens required to maintain connections to social platforms. These tokens are used only to provide functionality authorised by the Customer.
When a Customer disconnects a social channel, CreatorsPA’s access to the channel stops; the relevant access credentials are revoked or invalidated where technically available; and CreatorsPA stops retrieving new information from that connection.
Disconnecting a channel inside CreatorsPA also deletes the data stored for that channel in the same action — comments, drafts, learned reply examples and channel records. It is not retained for later manual clean-up. If the Customer instead revokes access at the platform without disconnecting inside CreatorsPA, our access stops but the previously stored data is not yet removed automatically; it can be removed by disconnecting the channel or deleting the account.
28. YouTube Data
YouTube data is subject to additional requirements imposed by Google and YouTube. Where the Customer disconnects a YouTube channel inside CreatorsPA, the associated YouTube API data is deleted immediately as part of that action. Where authorisation is instead revoked at Google, expires or can no longer be verified, CreatorsPA does not currently detect that automatically; the data is deleted when the Customer disconnects the channel or deletes the account, and on request within the period required by applicable YouTube policies.
This requirement may apply even where historical data from other connected platforms remains in the Customer’s account. The Customer may also revoke CreatorsPA’s access through the Customer’s Google Account security settings.
29. Data Retention During Active Use
Customer Data is generally retained for as long as required to provide the features selected by the Customer. For example:
- saved conversations remain until the Customer deletes the conversation or account;
- stored Customer Content remains until deleted through the Service or the account is deleted;
- connected channel history is deleted when the channel is disconnected inside CreatorsPA;
- generated files stored in CreatorsPA remain until deleted according to the applicable account or content controls; and
- support information is retained only as long as reasonably necessary for support, security, dispute resolution or legal requirements.
CreatorsPA may retain limited operational or compliance records for longer where required by law or reasonably necessary to establish that an action, consent or deletion occurred. Where possible, such records may be anonymised.
30. Account Deletion
Account deletion in CreatorsPA is immediate and irreversible. There is no deactivation state and no recovery period.
The Customer confirms deletion by typing a confirmation word, after which third-party access is revoked where technically possible, stored files are deleted, any voice copies are permanently deleted at the applicable voice provider, and the account is deleted together with the data in every connected table.
CreatorsPA cannot restore an account after deletion.
Two limited types of records are deliberately retained: usage records required for accounting, with the account identifier removed, and records showing that voice consent was given and that voice deletion was carried out. Those records may contain an account identifier but do not contain Customer Content.
31. Backup Retention
When Customer Data is permanently deleted from active systems, deleted files such as stored images and voice files are removed from active storage; deleted database information may remain temporarily in encrypted backups for up to seven days; and those backups are then overwritten through the normal backup cycle.
Backup copies are isolated from ordinary production use and are used only for legitimate backup or disaster-recovery purposes. If a backup must be restored, CreatorsPA will take reasonable steps to ensure that data previously scheduled for permanent deletion is not returned to ordinary use.
32. Individual Deletion Requests
Customers may use the deletion functionality provided within CreatorsPA to remove data supported by those features. In exceptional circumstances, a Customer may contact info@creatorspa.io to request accelerated or additional deletion.
CreatorsPA will consider such requests reasonably but does not guarantee that a special deletion request can be completed outside the normal functionality or retention processes unless required by Applicable Data Protection Law.
33. Return and Export of Data
While an account is active, Customers may use available export functionality to obtain Customer Data supported by the Service.
Because account deletion is immediate and irreversible, there is no post-deletion recovery or export period.
Once account deletion has been confirmed, CreatorsPA cannot restore the account or provide an ordinary export of data that has been permanently deleted from active systems.
Limited records and encrypted backup data may remain only as described in Sections 30 and 31 of this DPA.
34. Operational and Security Logs
CreatorsPA retains operational and security information only for as long as reasonably necessary for security, troubleshooting, abuse prevention, compliance, dispute resolution, accounting or legal obligations.
CreatorsPA does not build advertising or analytics profiles from technical activity. CreatorsPA records the Customer’s last sign-in date for account and inactivity management. CreatorsPA does not maintain its own tracking profile containing IP address, device or browser history for advertising or analytics. Infrastructure providers such as hosting or database providers may process IP addresses and similar technical information as necessary to deliver and secure their services.
35. Automated Decision-Making
CreatorsPA does not use Customer Data to make solely automated decisions about an individual that produce legal effects or similarly significant effects within the meaning of applicable Data Protection Law. Automated security or abuse-detection systems may flag activity for review or technical intervention, but this does not change the Customer’s rights under applicable law.
36. Government and Legal Requests
If CreatorsPA receives a legally binding request from a public authority concerning Customer Data, CreatorsPA will handle the request in accordance with applicable law. Where legally permitted and reasonably possible, CreatorsPA may inform the affected Customer before disclosing Customer Data.
CreatorsPA will not voluntarily provide Customer Data to a public authority except where required by law, necessary to protect rights or safety in an emergency, or otherwise permitted under Applicable Data Protection Law. Where the SCCs apply, CreatorsPA will comply with the government-access obligations contained in those SCCs.
37. Term and Termination
This DPA begins when the Customer accepts the CreatorsPA Terms of Use and applies for as long as CreatorsPA processes Customer Data on behalf of the Customer. The DPA does not require a separate signature.
Where CreatorsPA materially breaches this DPA, the Customer must first provide CreatorsPA with a reasonable opportunity to remedy the breach where the breach is capable of remedy. Termination rights apply where required by Applicable Data Protection Law, required by the applicable SCCs or UK Addendum, a material breach cannot reasonably be remedied, or a material breach remains unremedied after a reasonable opportunity to correct it.
Termination does not remove obligations concerning confidentiality, deletion, liability, international transfer protections or other provisions that by their nature survive termination.
38. Liability
The liability provisions and limitations contained in the CreatorsPA Terms of Use apply to this DPA.
For Customers using the Service for business or professional purposes, to the maximum extent permitted by applicable law, Mangroove FZ-LLC’s aggregate contractual liability arising out of or relating to this DPA will not exceed USD 100.
Nothing in this DPA limits or excludes liability where such limitation or exclusion is prohibited by Applicable Data Protection Law, the SCCs, the UK Addendum or another mandatory legal requirement.
Where the Customer is a consumer, nothing in this Section limits any mandatory consumer rights.
The SCCs or UK Addendum prevail to the extent their mandatory liability provisions conflict with this Section.
39. Costs of Assistance
Normal compliance with CreatorsPA’s obligations as Processor is included as part of the Service. Where the Customer requests significant assistance beyond the standard functionality or ordinary legal obligations of CreatorsPA, including bespoke audits, extensive Data Subject request assistance, regulatory support or custom technical work, CreatorsPA may charge reasonable costs for that assistance. CreatorsPA will inform the Customer before incurring material additional charges where reasonably practical.
40. Order of Precedence
If there is a conflict between documents governing the processing of Customer Data, the following order applies: (1) mandatory provisions of Applicable Data Protection Law; (2) applicable SCCs or UK Addendum; (3) this DPA; (4) the CreatorsPA Terms of Use. This order applies only to the extent of the relevant conflict.
41. Governing Law
Except for international transfer provisions that require a different governing law, this DPA is governed by the laws of the United Arab Emirates. Subject to mandatory rights and the transfer provisions above, disputes concerning this DPA are subject to the courts of Ras Al Khaimah, United Arab Emirates.
Where the EU SCCs apply, their mandatory governing-law and jurisdiction provisions apply to matters governed by those clauses. Where the UK Addendum applies, its mandatory governing-law and jurisdiction provisions apply to the relevant UK transfer.
42. Changes to this DPA
CreatorsPA may update this DPA where reasonably necessary to reflect changes in the Service, reflect changes in subprocessors, comply with changes in law, implement new regulatory guidance, improve privacy or security protections, or clarify existing obligations. Material changes will be communicated in accordance with the Terms of Use and Applicable Data Protection Law. No amendment may reduce protections required by mandatory Applicable Data Protection Law.
43. Contact
Questions about this DPA, data protection or Security Incidents may be sent to info@creatorspa.io.
Mangroove FZ-LLC currently manages privacy matters internally and has not appointed a formal Data Protection Officer.
Schedule 1 — Details of Processing
A. Subject Matter
Processing of Personal Data reasonably necessary for CreatorsPA to provide content-creation, AI, social-channel, publishing, support, calendar and related functionality selected by the Customer.
B. Duration
For the duration of the Customer’s use of the Service and, following termination or account deletion, only for the limited retention, backup or legal-compliance periods described in this DPA.
There is no account recovery period following deletion.
C. Nature of Processing
Collection; access; transmission; storage; organisation; retrieval; consultation; generation; adaptation; display; analysis; publication at the Customer’s instruction; deletion; restriction; backup; and other processing necessary to provide the Service.
D. Purposes
Providing requested CreatorsPA features; storing Customer Content; maintaining conversational context; AI generation requested by the Customer; trend research; managing connected social accounts; retrieving comments and platform information; scheduling and publishing Customer-approved content; creating Google Calendar events at the Customer’s request; providing technical support; maintaining security; preventing abuse; troubleshooting; backup and disaster recovery; and complying with lawful instructions.
E. Types of Personal Data
Names; usernames; social profile information; social channel identifiers; comments; textual content; images; photographs; voice recordings; video; likenesses; conversation content; prompts; AI-generated content; YouTube titles and descriptions; publishing history; OAuth tokens; links to platform-hosted media; calendar-event information processed transiently; support information; and other Personal Data voluntarily supplied by the Customer through the Service.
F. Categories of Data Subjects
The Customer; people appearing in Customer Content; commenters and social-channel users; collaborators; customers or clients of the Customer; other persons referenced in Customer Content; and minors lawfully appearing in Customer Content.
G. Special Category Data
CreatorsPA is not intended for the intentional processing of special category Personal Data. Biometric identification is not performed.
Schedule 2 — Technical and Organisational Measures
CreatorsPA currently maintains measures including:
Encryption
- TLS encryption in transit.
- AES-256 encryption at rest through the storage infrastructure.
- Encrypted database backups.
Access Control
- database row-level security;
- restricted production access;
- authorised personnel only;
- need-to-know access;
- confidentiality obligations; and
- separation of user access.
Application Security
- secrets stored in secure hosting environment variables rather than source code;
- controlled production access;
- restricted administrative functionality; and
- logging of sensitive administrative actions.
Data Minimisation
- AI processing only when the Customer activates the relevant feature;
- only recent conversation context required for an AI request is transmitted where appropriate;
- no permanent storage of connected-platform analytics history;
- no storage of payment card or bank details by CreatorsPA;
- no advertising tracking; and
- no independent device or browser tracking profile.
Storage and Backup
- primary Customer Data storage in the European Union;
- encrypted backups;
- database information may remain in encrypted backups for up to seven days following permanent deletion;
- backup data is used only for legitimate backup or disaster-recovery purposes; and
- permanently deleted account data is not restored for ordinary use.
Personnel Security
- production access limited to authorised personnel;
- access only for legitimate operational purposes;
- confidentiality obligations; and
- need-to-know access principles.
Incident Management
CreatorsPA maintains procedures intended to identify suspected incidents; investigate and contain incidents; document confirmed incidents; mitigate adverse effects; preserve relevant evidence; implement corrective measures; and notify affected Customers without undue delay where required.
Service Providers
Subprocessors are required to be subject to appropriate data protection obligations and international transfer safeguards where required.
Schedule 3 — International Transfer Information
Data Exporter
The Customer identified through the CreatorsPA account and Terms of Use. Role: Controller, in the ordinary case; or Processor where the Customer processes Personal Data on behalf of another Controller.
Data Importer
Mangroove FZ-LLC, Licence No. 47035430, Ras Al Khaimah, United Arab Emirates. Role: Processor / Subprocessor. Contact: info@creatorspa.io
Transfer Frequency
Continuous or intermittent for the duration of the Service, depending on the features used by the Customer.
Transfer Purpose
To provide the functionality described in this DPA.
EU SCC Module
Module Two where Customer is Controller and CreatorsPA is Processor. Module Three where Customer is Processor and CreatorsPA is Subprocessor.
EU SCC Governing Law and Courts
Ireland, where a choice is required under the SCCs.
Technical and Organisational Measures
The measures described in Schedule 2 apply.
Subprocessors
The current list is maintained on the CreatorsPA Subprocessors page.
UK Transfers
Where required, the UK International Data Transfer Addendum applies together with the relevant EU SCC module.